Re: [PATCH v3 net 0/3] udp: Fix two integer overflows when sk->sk_rcvbuf is close to INT_MAX.
From: Jakub Kicinski <kuba@kernel.org>
Date: 2025-03-29 14:53:16
On Thu, 27 Mar 2025 13:26:52 -0700 Kuniyuki Iwashima wrote:
I got a report that UDP mem usage in /proc/net/sockstat did not drop even after an application was terminated. The issue could happen if sk->sk_rmem_alloc wraps around due to a large sk->sk_rcvbuf, which was INT_MAX in our case. The patch 2 fixes the issue, and the patch 1 fixes yet another overflow I found while investigating the issue.
Test fails in the CI, unfortunately: # 0.00 [+0.00] TAP version 13 # 0.00 [+0.00] 1..2 # 0.00 [+0.00] # Starting 2 tests from 2 test cases. # 0.00 [+0.00] # RUN so_rcvbuf.udp_ipv4.rmem_max ... # 0.00 [+0.00] # so_rcvbuf.c:150:rmem_max:Expected get_prot_pages(_metadata, variant) (49) == 0 (0) # 0.01 [+0.00] # rmem_max: Test terminated by assertion # 0.01 [+0.00] # FAIL so_rcvbuf.udp_ipv4.rmem_max # 0.01 [+0.00] not ok 1 so_rcvbuf.udp_ipv4.rmem_max # 0.01 [+0.00] # RUN so_rcvbuf.udp_ipv6.rmem_max ... # 0.01 [+0.00] # so_rcvbuf.c:150:rmem_max:Expected get_prot_pages(_metadata, variant) (49) == 0 (0) # 0.01 [+0.00] # rmem_max: Test terminated by assertion # 0.01 [+0.00] # FAIL so_rcvbuf.udp_ipv6.rmem_max # 0.01 [+0.00] not ok 2 so_rcvbuf.udp_ipv6.rmem_max # 0.02 [+0.00] # FAILED: 0 / 2 tests passed. # 0.02 [+0.00] # Totals: pass:0 fail:2 xfail:0 xpass:0 skip:0 error:0 not ok 1 selftests: net: so_rcvbuf # exit=1 -- pw-bot: cr